Firewalls Flashcards

1
Q

Firewalls

A
  • specialized software modules running on computer or dedicated network
  • filter packets coming in and out of network
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the most basic feature of a firewall?

A

packet filtering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some characteristic rules for packet filtering?

A

source IP, destination IP, protocol, source port, destination port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How do packet filters work?

A

the inspect the header of every packet and then make a decision how to treat it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Most common packet filtering actions

A
  1. Allow
  2. Drop (no notification)
  3. Deny (notifies source host)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Application Layer (7) Firewalls

A

check all OSI 7 layers

  • inspect actual content of packet
  • prevent users from visiting a site
  • drop peer2peer application packet
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IDS: Intrusion Detection Systems

A
  • inspect app payload to detect potential attack
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does an IDS check for?

A

ongoing intrusions: ping sweeps, port scans, SQL injections, buffer overflows, etc
- identify traffic generated by virus/worm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does IDS detect risky traffic?

A

signatures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can IDS detect something it does not already know?

A

No

- sometimes false positives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Detection sensors

A
  • software components that inspect network traffic

- passively intercept intrusions and comms to IDS manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

IDS Manager

A

software in charge fo maintaining policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

2 main categories of IDS

A
  1. Network Intrusion Detection Systems (NIDS)

2. Host Intrusion Detection Systems (HIDS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

NIDS: Network Intrusion Detection Systems

A

inspect network traffic w/ sensors placed on router or DMZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

HIDS: Host Intrusion Detection Systems

A

monitor logs, file-system changes, OS config changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

IPS: Intrusion Prevention Systems

A
  • drop malicious requests when the threat has a risk classification above a pre-defined threshold
17
Q

How to spot an obstacle like firewall/IDS/etc?

A

TCP SYN is sent:

  1. no TCP SYN/ACK reply
  2. TCP RST/ACK reply is received
18
Q

NAT: Network Address Translation

A

technique used to provide access to a network from another network
- masquerades client’s IP address to external internet